01Who we are
Checkbox is operated by CHECKBOX, LLC, a limited liability company based in Puerto Rico, USA ("Checkbox", "we", "us"). This policy covers the Checkbox mobile apps for iOS and Android, the web app and every page at checkbox.my. For anything in this policy, write to support@checkbox.my.
02What we collect
Your account
Name, email address and a password (stored only as a secure hash by our authentication provider — we never see it), plus the preferences you set: language, theme, notification choices, and the organizations and circles you belong to.
Private-access requests
If you request access before public signup opens, we store the email address, platform and optional use category you submit, together with the page source, language, selected plan or billing interval, campaign tags and the consent version shown on the form. We use this only to manage access and send product- access email. Supabase stores the request and Resend may deliver the follow-up. We do not store a raw IP address; abuse controls retain only a keyed one-way hash for up to 48 hours.
The content you create
Checkbox is a place where you record real work, so your content is the heart of the product: plans, goals, rules, checkboxes and their completions; photos and videos you attach as proof; documents you upload or generate; form and table values; notes and signatures; chat messages in your circles and direct messages with your coach; and the audio/video of live sessions you join.
Location — only to validate, never to track
If a checkbox is configured with location validation, we capture your precise location at the moment you complete it (or when you check in at a defined place) and store it as part of that completion record. That is the entire use. There is no background location, no location history, and no movement tracking — the permission is "while using the app" only, and only fires when a location-validated checkbox asks for it.
Health signals — only if you connect them
If you explicitly connect Apple Health or Health Connect, Checkbox reads only the signals you choose (such as steps, workouts, sleep or weight) to verify the goals you set. Only each day's total leaves your phone — never raw samples, never continuous streams. We never write to your health data, never use it for advertising, never sell it, and never share it with third parties. You can disconnect at any time in your device's settings, and deleting your account deletes the stored totals.
Push tokens
When you enable notifications we store the push token your device issues so we can deliver reminders, alerts and messages. Tokens are removed when they become invalid or when your account is deleted.
Usage and diagnostics
Crash and performance reports help us fix problems. When configured and enabled, Sentry receives the device model, operating-system version, app version and a technical trace of the error — never your evidence content. The marketing site contains a consent-aware measurement adapter, but no marketing analytics provider is currently active, so those events are not transmitted. We will update this policy before enabling one. Diagnostics are for engineering, not advertising, and are never sold. In-app controls appear under Profile → Privacy where the relevant service is enabled.
Connected apps
If you connect an external tool (for example Google Calendar or Google Sheets) to verify a goal, Checkbox accesses only the minimum needed for the check you configured — for example, whether an event exists or a cell changed. What each connection can read is listed in Settings → Connections in plain words, and you can disconnect or revoke it there at any time.
Google user data
If you connect Google Calendar, Checkbox requests read-only access to your calendar list and events (scopes: calendar.calendarlist.readonly, calendar.events.readonly). We use it for exactly one thing: answering the verification questions you configure — for example, whether an event named "Gym" existed today, or whether you had no meetings after 6 PM. We store the answers (counts and minutes), not copies of your calendar.
If you connect Google Sheets, Checkbox uses the drive.file scope: we can only see the specific spreadsheet files you pick in Google's own file picker — never your Drive. From a picked file we read the cell or range you choose and store its value as evidence for the rule you configured.
OAuth tokens are encrypted at rest, are never sent to your device or any client, and are deleted — and revoked with Google — when you disconnect. Disconnecting keeps your evidence history; revoking can also erase every observation the connection produced, immediately.
Checkbox's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it for advertising, and no human reads it except with your consent, for security purposes, or to comply with applicable law.
03How we use it
- To run the product — validate completions, compute your score, sync your organizations, deliver messages and live sessions.
- To keep records honest — completions and their evidence form the accountability record your plan, team or audit depends on.
- To notify you — reminders, alarms, alerts and messages you signed up for. Every category can be turned off.
- To provide support — when you write to us, we look at your account to help you.
- To keep the service safe — abuse prevention, moderation of reported content, and security monitoring.
04What we never do
- We never sell or rent your personal data. To anyone.
- We show no third-party advertising, so no ad networks receive your data.
- We do not track you across other companies' apps or websites.
- We never use your health data or your location for anything except the validations you configured.
- We never use your content to train AI models.
05Who can see your content
Checkbox is built for accountability, which is social by design — but visibility always follows the structure you chose:
- Your organizations and circles — content you create inside an organization is visible to its members according to their roles. Completions of tasks assigned to you are visible to the people who supervise them.
- Your coach — if you subscribe to a coach, they see the progress of the plans they run for you, and your direct messages with them.
- Live sessions — people in the session see and hear what you share while you share it.
- Nobody else. We disclose data outside the product only if the law genuinely requires it, or to protect the safety and integrity of the service.
06Service providers
A small set of infrastructure providers process data on our behalf, under contract, only to run Checkbox:
| Provider | What it does for Checkbox |
|---|---|
| Supabase | Database, authentication and file storage — where your account and content live. |
| LiveKit | Real-time audio/video infrastructure for live sessions. |
| Stripe, Apple App Store and Google Play | Payment processing for web and native-store purchases. Payment credentials go directly to the applicable provider — Checkbox does not store full card numbers. |
| Expo | Delivery of push notifications to your device. |
| Push delivery on Android (Firebase Cloud Messaging), maps for location validation — and, only if you connect them, the Google services you choose (e.g. Calendar, Sheets). | |
| Resend | Transactional email (invitations, alerts, account email). |
| Sentry | Crash and error reporting, so we can fix problems fast. Can be turned off in Profile → Privacy. |
07How long we keep data
- Account and content — kept while your account is active; deleted when you delete your account (see below).
- Private-access requests — kept for up to 24 months after the latest request, or deleted earlier if you ask us at support@checkbox.my.
- Live session replays — automatically deleted 30 days after the session.
- Location points — kept as part of the completion record they validate, for as long as that record exists.
- Push tokens — removed when invalid, on sign-out cleanup, or with account deletion.
- Backups — encrypted backups rotate out within 30 days of deletion.
08Deleting your account
Account deletion is built into the app: Profile → Delete account. The flow explains exactly what will happen, asks you to re-enter your password, and is irreversible. When you delete your account:
- Your identity — name, email, credentials, push tokens and personal content — is erased.
- Circles where you were the only member are deleted entirely.
- Work you completed for other organizations remains as their compliance record, but anonymized — your identity is detached from it.
No app access? See checkbox.my/delete-account for the request path by email.
09Your rights
You can access, correct, export or delete your data. Most of it you can do directly in the app; for anything else, email support@checkbox.my from your account address and we will act on it within 30 days. Depending on where you live, these rights may be backed by specific laws (such as GDPR or state privacy acts) — we honor the same requests for everyone, regardless of geography.
10Security
All traffic is encrypted in transit (TLS). Data is stored encrypted at rest. Every database query runs behind row-level security, so your data is only reachable through the permissions of your role in each organization. Access by our own team is limited to what support and operations require.
11Children
Checkbox is not directed to children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, write to us and we will delete it.
12Where data lives
Checkbox is operated from Puerto Rico, USA, and our providers store data in the United States. If you use Checkbox from elsewhere, your data is processed in the US under this policy.
13Changes
If we change this policy in a way that matters, we will update the date at the top and tell you in the app before the change applies. The current version always lives at checkbox.my/privacy.
14Contact
CHECKBOX, LLC — Puerto Rico, USA
Privacy & data requests: support@checkbox.my
Support center: checkbox.my/support